CVE-2025-62326: HCL Digital Experience is susceptible to stored cross-site scripting (XSS)
Published Feb 20, 2026
·Updated
HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.
Affected Software
2 affected components
HCL Digital Experience
hcltech Digital Experience=9.5
Event History
Feb 20, 2026
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:25 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62326?
CVE-2025-62326 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-62326?
To remediate CVE-2025-62326, apply the latest patches provided by HCL for Digital Experience.
3
Who is affected by CVE-2025-62326?
CVE-2025-62326 affects any instance of HCL Digital Experience with administrative access.
4
Can CVE-2025-62326 be exploited remotely?
CVE-2025-62326 requires elevated privileges; hence, it cannot be exploited remotely by an unauthenticated user.
5
What type of vulnerability is CVE-2025-62326?
CVE-2025-62326 is a stored cross-site scripting (XSS) vulnerability.